In June, Anthropic released two of its most capable AI models to date. Within days, the US government ordered the company to cut off access for every user outside the country, citing national security concerns.
Anthropic had no reliable way to check who was logging in from where. So, it pulled the models entirely, for everyone, including its own American customers. Two and a half weeks later, the controls were lifted and access came back. One of the two models remains restricted to a small number of approved organizations in the US.
That sequence of suspend, restore, and partially restrict is worth looking at. It shows that access to the AI tools a business has built into its operations can change on a government's timetable rather than its own, with little or no notice.
For security leaders, that's the new reality to plan around. Risk is concentrated in a small number of providers, regulation hasn't caught up, and the only thing properly within your control is how well you've covered the fundamentals of security.
Building resilience
The episode has since become something of a reference point in wider discussions about AI sovereignty, and rightly so.
But the mistake would be treating it as a story about one vendor and one fortnight in June. The pattern behind it was already visible before this happened, and it remains visible now. Critical AI capability is concentrated among a small number of providers, whose commercial, policy, or regulatory position can shift with limited warning.
Export-control regimes on frontier AI are still forming and not yet settled. Meanwhile, several governments have used the past few months to accelerate their own sovereign AI investment instead of waiting to see whether the risk repeats itself.
Businesses need to realize that the practical lesson here isn't to predict the next disruption. Instead, it’s to assume that AI access, functionality, and governance requirements will keep evolving, sometimes abruptly, and to build resilience accordingly.
Resilience in this context has a fairly specific meaning. It’s about knowing where AI is embedded across the business, understanding which processes and teams depend on which tools, and having a contingency plan ready before something changes.
Organizations that could answer those questions in June were in a materially better position than those still working it out as the news broke.
Independent validation is still essential
When the export controls were lifted, it followed an agreement between Anthropic and the US government on how future risks would be flagged and reviewed. That's a start, but it's still one company and one government working the problem out between themselves, with the terms set largely behind closed doors.
OpenAI's response to its own security incident follows the same pattern. After one of its models breached Hugging Face's systems during testing, the company paused its largest frontier training run and introduced new internal safeguards, on its own timeline, using its own judgement about what the incident required.
Two of the industry's biggest players are currently setting their own terms for how AI risk gets identified and addressed, and businesses are expected to simply trust that the terms are adequate.
Initiatives like the International Network of AI Safety Institutes exist for good reason – no single vendor should be marking its own homework on how safe or how risky a model is. Yet these bodies remain government led, so strengthening their independence should be a priority.
That doesn't mean you should wait for global governance to mature. Be proactive by building your own capability to question what a vendor or a regulator tells you, rather than accepting it at face value.
It starts with visibility
Most importantly, you can't secure, govern or build resilience around something you can't see. This is the practical starting point and it's where most organizations' AI risk breaks down.
Ask businesses for a complete inventory of the AI technologies running across their operations, and many will give an estimate rather than a concrete answer. Models get adopted department by department, sometimes officially, often not. Data flows into and out of them without a central record of where, or governance to control who has access.
None of this is unusual. It's simply what happens when adoption outpaces oversight, which is where a lot of organizations currently are with AI.
The fix isn't complicated, even if it takes discipline to maintain. A working inventory needs to answer four things for every AI tool in use – where the model sits, what data it can access, who has access to it, and how a change in vendor policy, regulation or export control could affect the processes built around it.
That last point is the one the events in June exposed. For now, the key lesson for organizations is to understand the environment they’re protecting and to know the gaps in their defenses alongside a fully tested business continuity plan. Those fundamentals will matter more than anything else in the coming months as this new landscape remains highly unpredictable.
Visibility of that kind can turn a scramble into a known, manageable problem around which parts of the business are exposed, what the fallback looks like, and how long it takes to execute. That's the difference between reacting to disruption and being ready for it.
Governments and vendors will keep shaping the terms of AI access. Businesses that know their own dependencies will be the ones still standing tall when the terms change again.
We've featured the best endpoint protection software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
1 hour ago
1

